dnsbox 0.0.1

High-performance, zero-copy DNS message parsing and building for requests and responses, with broad RFC extension coverage.
Documentation
# Security Policy

## Threat model

`dnsbox` parses DNS messages from **untrusted sources** (network peers,
captures, zone data). Its parsers are written to that bar:

- **No panic, no out-of-bounds reads on malformed input.** Malformed
  messages are rejected with an `Error` variant rather than aborting.
- **No memory-unsafety.** The crate is `#![forbid(unsafe_code)]`.
- **Bounded work per message.** Name decompression rejects pointer loops and
  caps the number of hops, so a small message cannot cause unbounded CPU use.

The crate does **not** claim any cryptographic property of its own; DNSSEC
and TSIG verification, when added, delegate to pluggable crypto backends.

## Reporting a vulnerability

Please report vulnerabilities privately through GitHub's
[security advisory form](https://github.com/KarpelesLab/dnsbox/security/advisories/new)
rather than opening a public issue.